Description
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
Published: 2026-08-13
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated local user to delete files arbitrarily with elevated privileges, effectively enabling a privilege‑escalation attack that can destroy critical data. The flaw is a boundary‑violating path traversal weakness, mapped to CWE‑59. Consequently, attackers can compromise data integrity and potentially affect system integrity if essential files are removed.

Affected Systems

Lenovo Dock Manager, as shipped on Lenovo workstations and docking stations. No specific affected version range is listed; administrators should verify the currently installed version of the Dock Manager component.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. EPSS information is not available and the vulnerability is not in CISA KEV, implying no documented widespread exploitation. The attack vector is inferred to be a local authenticated user with the ability to elevate privileges; therefore exploitation is largely confined to the local host. The risk hinges on the ability to delete files that may be critical to system operation or user data, potentially leading to denial of service or facilitating further compromise. No public exploits are known, so the threat is primarily theoretical at this time.

Generated by OpenCVE AI on August 13, 2026 at 16:46 UTC.

Remediation

Vendor Solution

Update Lenovo Dock Manager to version 1.6.5.3 or later.


OpenCVE Recommended Actions

  • Update Lenovo Dock Manager to version 1.6.5.3 or later, which fixes the privilege escalation flaw.
  • Restrict local accounts that can run Dock Manager with elevated privileges, limiting their ability to delete essential system files until a patch is applied.
  • Monitor system logs for unexpected file deletion events and investigate any anomalies promptly.

Generated by OpenCVE AI on August 13, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local User Can Delete Files with Elevated Privileges in Lenovo Dock Manager

Thu, 13 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
First Time appeared Lenovo
Lenovo dock Manager
Weaknesses CWE-59
CPEs cpe:2.3:a:lenovo:dock_manager:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo dock Manager
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Dock Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-08-13T15:59:01.720Z

Reserved: 2026-07-16T19:22:22.180Z

Link: CVE-2026-63426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T15:19:55.517

Modified: 2026-08-13T16:18:32.447

Link: CVE-2026-63426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:45:03Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')